← Back to results

Staff Product Security Engineer (Security)

Join Phantom as a Staff Product Security Engineer to enhance security across mobile, web, and backend products for millions of users.

Location
United States
Compensation
$200k–$250k/yr
Level
staff
Type
full time · Remote

Posted by employer 1 day ago

First seen on Joblaze 9 hours ago

Last verified on the company career page 9 hours ago

Apply at Phantom → Save job Scanned from phantom.app

What you'll build

  • Identify and address security risks across products
  • Lead security reviews for new products
  • Embed security controls into the software development lifecycle
  • Perform AI assisted security code reviews
  • Support investigation of product security incidents

Must have

  • 5+ years of experience in product security
  • Strong understanding of web, mobile, API, and distributed-system security
  • Hands-on experience building AI-assisted security tooling
  • Demonstrated ability to review production code in one or more languages

Nice to have

  • Experience securing consumer financial products
  • Familiarity with blockchain systems
  • Experience securing browser extensions or native mobile applications
  • Experience working with bug bounty programs

Role intensity

60% hands-on coding

AI in the day-to-day

We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work.

Requirements

Experience
5+ years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Unlimited PTO Equity/Stock Options Remote Work Health Insurance

Joblaze summary

In this role, the Staff Product Security Engineer at Phantom is responsible for identifying and mitigating security risks across various platforms, including mobile and web applications. The position requires expertise in application security, threat modeling, and the development of AI-assisted security tools, with a strong emphasis on hands-on involvement in code review and vulnerability management. This role is suited for experienced security engineers who can lead initiatives and collaborate effectively with engineering teams. Phantom's focus on security within a rapidly growing fintech environment adds a layer of complexity and impact to the work.

Joblaze insights

  • Listed today — first seen on Joblaze September 23, 2026. Last confirmed on Phantom's careers page September 23, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 42% of 36 comparable staff security roles in United States that list Python we track (median $200,000 across 21 companies). See Python salary trends
  • Python appears in 48.9% of 88 comparable staff security roles in United States; AI appears in 4.5% of 88 comparable staff security roles in United States.

Quick facts

Is the Staff Product Security Engineer (Security) role remote?
Yes — Phantom lists this as a fully remote position.
What's the salary range?
Phantom lists $200,000–$250,000 for this role.
How much experience is required?
At least 5 years of relevant experience for this Staff Product Security Engineer (Security) role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, AWS, Go, JavaScript, Kubernetes, Python.
What seniority level is this role?
Phantom targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Product Security Engineer (Security) role at Phantom.

From the original posting

Security is core to Phantom’s product and the trust millions of users place in us. We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work—from code review and threat modeling to vulnerability discovery and security automation. We’re looking for strong security engineers with high agency who can identify the risks that matter, build practical solutions, and take ownership from initial discovery through verified remediation.

This is a hands-on, high-impact role spanning architecture, source code, testing, and production systems across Phantom’s mobile, web, and backend products. You’ll work directly with engineering and product teams, lead complex security initiatives, and build capabilities that scale across the company. At the Staff level, you’ll set technical direction and raise the bar for how Phantom designs, builds, and ships secure products.

This role is fully remote and open to candidates based in the US, UK and Canada.

Responsibilities

  • Product Security Ownership: Partner with engineering teams to identify and address security risks across Phantom’s mobile applications, web products, APIs, and backend services.

  • Architecture and Threat Modeling: Lead security reviews for new products and major architectural changes, with particular attention to authorization boundaries, sensitive data, transaction integrity, key material, and third-party integrations.

  • Secure Product Development: Embed practical security controls into the software development lifecycle, from design and implementation through testing, release, and production operation.

  • Code Review and Security Testing: Perform AI assisted security code reviews and targeted testing of high-risk features. Build repeatable approaches that help find vulnerabilities before they reach production.

  • Security Tooling: Develop and improve tooling that gives engineers fast, actionable security feedback without creating unnecessary friction. Use automation and AI-assisted workflows where they materially improve coverage or speed.

  • Software Supply Chain Security: Harden CI/CD, build, and release systems against supply chain threats, including dependency risk, secrets exposure, build provenance, artifact integrity, and compromised developer or automation workflows.

  • Vulnerability Management: Triage findings from internal testing, researchers, bug bounty submissions, and third-party assessments. Work with owners to determine real-world impact and drive issues through verified remediation.

  • Incident Response: Support the investigation of product security incidents and suspicious activity. Turn lessons from incidents into durable improvements to product architecture, detection, and engineering standards.

  • Technical Leadership: Establish product security patterns and expectations across engineering. At the Staff level, lead ambiguous, cross-functional initiatives and influence architecture beyond any single product team.

Qualifications

  • 5+ years of experience in product security, application security, security engineering, or software engineering, including experience operating at a senior or staff level.

  • Strong understanding of web, mobile, API, and distributed-system security, including authentication, authorization, session management, cryptography, and common vulnerability classes.

  • Hands-on experience building or applying AI-assisted security tooling to test applications and APIs, combining automated analysis with source-code review and manual validation.

  • Demonstrated ability to review production code in one or more languages such as TypeScript, JavaScript, Rust, Python and Go.

  • Experience securing software supply chains and CI/CD systems, including dependencies, build infrastructure, secrets, artifacts, signing, and release integrity.

  • Experience threat modeling complex products and translating security risks into concrete engineering requirements.

  • Strong judgment when evaluating exploitability, business impact, and appropriate remediation.

  • Track record of partnering effectively with engineering and product teams while maintaining a high security bar.

  • Clear written and verbal communication, including the ability to explain technical risk to both engineers and non-security stakeholders.

Nice To Haves

  • Experience securing consumer financial products, wallets, payments, or other systems where client integrity and transaction safety are critical.

  • Familiarity with blockchain systems, smart-contract interactions, transaction simulation, signing workflows, or self-custodial wallet architecture.

  • Experience securing browser extensions or native mobile applications.

  • Experience building and integrating application-security tooling, static or dynamic analysis, security test infrastructure, or policy-as-code controls.

  • Familiarity with AWS, Kubernetes, CI/CD systems, and cloud-native service architectures.

  • Experience working with bug bounty programs or coordinating external security assessments.

Why Work with Us

Phantom is built by a team of experienced product and engineering leaders working to make crypto-powered finance safer and easier to use. Our products serve a large and rapidly growing global community, which makes security engineering here both technically challenging and directly consequential.

This role offers the opportunity to:

  • Protect products used by tens of millions of people.

  • Work on security problems spanning mobile, browser, backend, cloud, and blockchain systems.

  • Shape product architecture early rather than reviewing security only at the end.

  • Build durable security capabilities while the company and product surface continue to grow.

  • Work with engineers who care deeply about product quality, user experience, and security.

Benefits

  • Competitive salary and equity

  • Eligibility to participate in the company’s performance bonus program

  • Comprehensive medical, dental, and vision insurance with 100% coverage

  • Stipend for your ideal remote setup

  • Flexible hours and a supportive remote environment

  • Unlimited vacation—take time when you need it

  • 401(k) retirement plan

  • Monthly wellness benefit

  • Weekly meal benefit

  • Global off-sites

The target base salary for this role will range between $200,000 to $250,000 with the addition of equity and benefits. This is determined by a few factors including your skillset, prior relevant experience, quality of interviews and market factors (such as location) at the point in time of offer.

Standard company text repeated across Phantom's postings is omitted here.

Similar positions